Jump to content

Recommended Posts

VSGERFX
Posted

system: Windows 11 25H2
Kaspersky version standard edition :21.23.6.614 (a)
Last night, Kaspersky's background scan detected a virus
User Type: Active User
Component: Virus Scanning
Result: Detected
Result description: Detected
Type: Trojan
Name: MEM:Trojan.Win32.SEPEH.gen
Precision: Accurate
Threat Level: High
Object type: File
Object Name: System
Object path: pmem:\
Reason: Expert Analysis
Database Release Date: Today, 2026/7/4 15:06:00
I then began the cleanup process for the virus. Kaspersky Standard Edition couldn't handle it, while other antivirus software failed to detect the virus. After disabling various startup items, the virus alerts persisted. Only in Safe Mode did everything function normally. I was truly at a loss about how to deal with this virus, so I sought help on the forum.
PS: The attachment contains the autoruns log. I changed the extension from arn to jpg to enable uploading

autoruns.jpg

harlan4096
Posted

Welcome to Kaspersky Community.

 

Please upgrade Your 21.23 to last version 21.25.

 

I was going to suggest You to run a scan with KRD2024, but looks like it is not available now, all its references have been disappeared, maybe temporal 🤔

  • Like 2
AlexeyK
Posted (edited)
1 час назад, VSGERFX сказал:

Kaspersky's background scan detected a virus

Contact support team. Provide them with a GSI log, and if possible - traces when reproducing the detection.

You can also ctreate a topic on some forums for malware removal, for example here. But I would prefer to contact support first.

Or try to perform a full antivirus scan in the OS safe mode (you need to start the AV manually). Or use KRD.

24 минуты назад, harlan4096 сказал:

it is not available now

Seems to be downloading.)

Screenshot_1.thumb.png.fec5d062d2a6fb9b46ad49a3790c890c.png

24 минуты назад, harlan4096 сказал:

upgrade Your 21.23 to last version 21.25.

You think the detection is related to the version? Unlikely.) 

In addition, an active infection is not the best time to upgrade the AV version.

Edited by AlexeyK
VSGERFX
Posted (edited)
1 hour ago, harlan4096 said:

Welcome to Kaspersky Community.

 

Please upgrade Your 21.23 to last version 21.25.

 

I was going to suggest You to run a scan with KRD2024, but looks like it is not available now, all its references have been disappeared, maybe temporal 🤔

Upgraded, but still not resolved. But thank you, I'll go find customer service

Edited by VSGERFX
AlexeyK
Posted
18 минут назад, VSGERFX сказал:

but still not resolved.

Surprisingly. Of course it won't be resolved. The detection doesn't depend on the product version. The version upgrading with an active infection in the system memory is at least not recommended.

harlan4096
Posted

It may be an active infection in memory... or it may be a false positive...

  • Like 1
Posted
2 hours ago, VSGERFX said:

Object path: pmem:\

Also ‘PMEM’ = Persistent Memory 🤔

  • Like 1
AlexeyK
Posted
6 минут назад, harlan4096 сказал:

or it may be a false positive...

So it is urgently necessary to upgrade the version for verification. And probably get additional problems because:

4.4. Kaspersky does not guarantee successful installation, stable Software operation, and resolution of problems in the following cases:

  • 4.4.1. Installation is performed on an infected device.
8 минут назад, Berny сказал:

PMEM

Just System memory, as in this thread screenshot. Plus:

Цитата

Object Name: System

  • Like 1
Posted

Hello,

This detection found a RAW PE in system memory, which was neither instantiated as a process nor as a DLL. Typically, a process allocates a memory block to place a PE file. Currently, there is a process in the system exhibiting this behavior, but this behavior was not detected at the moment it occurred. Instead, it was identified by the rootkit's idle scan feature.

  • Like 1

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now


×
×
  • Create New...